This repository has no published release yet. Until the initial 0.1.0 release, security fixes apply to the default branch. After releases begin, only the latest released version receives security fixes; generated projects must replace this statement with their own support policy.
The 0.0.0 value in release configuration is an automation baseline, not a published or supported release.
Report vulnerabilities privately through GitHub private vulnerability reporting: open this repository's Security tab and choose Report a vulnerability.
Do not use public GitHub issues, pull requests, discussions, chat channels, or other public forums for vulnerability reports.
Include as much of the following as possible:
- affected version, commit, or deployment identifier;
- a description of the issue and its security impact;
- steps to reproduce or a minimal proof of concept;
- relevant logs, screenshots, or traces; and
- suggested mitigations, if available.
The CodeMode execution boundary and deployment requirements are documented in docs/docs/security.md. Non-security bugs belong in GitHub issues as described in CONTRIBUTING.md.